1. General ProvisionsThis Privacy Policy (hereinafter referred to as the “Policy”) outlines the principles, purposes, and procedures for the collection, storage, use, and protection of personal data by the data controller (hereinafter referred to as the “Operator”).
The Operator is committed to respecting and protecting the privacy and personal data of its clients, contractors, and website visitors.
2. Data Controller Contact InformationEmail: opd-ip-padezhnovev@mail.ru
Regions of data processing: All regions of the Russian Federation
3. Purpose of Data ProcessingThe Operator collects and processes personal data for the following purposes:
- Provision of services to clients
- Establishing and maintaining communication with clients
4. Categories of Personal Data ProcessedThe Operator may process the following categories of personal data:
- Full name (last name, first name, patronymic/middle name)
- Date of birth
- Email address
- Residential address
- Phone number
- Profession and job title
- Employment details (including work experience and current employment information such as company name and bank account details)
- Education background
5. Categories of Data SubjectsThe personal data processing activities may involve the following categories of individuals:
- Clients
- Contractors
- Website visitors
6. Legal Basis for ProcessingPersonal data is processed based on one or more of the following:
- The data subject has given explicit consent to the processing of their personal data
- Processing is necessary for the performance of a contract to which the data subject is a party or to take steps at the request of the data subject prior to entering into a contract
The contract concluded with the data subject shall not include terms that infringe on the subject’s fundamental rights and freedoms.
7. Types of Data Processing Activities- Collection
- Recording
- Structuring
- Storage
- Updating or modification
- Retrieval
- Use
- Disclosure by transmission, dissemination, or otherwise making available
- Anonymization
- Restriction
- Deletion
- Destruction
8. Methods of Processing- Automated processing
- Internal network transmission
- Internet-based transmission
9. Security MeasuresThe Operator takes all reasonable organizational, technical, and administrative measures to ensure the protection of personal data from unauthorized or unlawful access, alteration, disclosure, or destruction.
These measures include but are not limited to:
- Internal policies and documentation regulating personal data handling
- Regular audits and internal controls
- Identification and assessment of security threats in information systems
- Detection of unauthorized access and incident response (including computer attack mitigation and investigation)
- Antivirus protection and cybersecurity tools provided by authorized service providers
- User authentication through conditional fixed passwords
10. Data Retention and DeletionPersonal data processing may be terminated in the following cases:
- Termination of the Operator’s business activities
- Withdrawal of the data subject’s consent, submitted by sending a written request via post or to the official email address. The request must include the full name and email address of the data subject
11. Data Security Assurance- Secure storage of physical and electronic data carriers
- Use of certified information security tools, when required to mitigate identified threats
- Implementation of appropriate safeguards to ensure the confidentiality and integrity of personal data